Beware: Fake Roblox Mod 'Xeno Executor' Spreads Malware, Steals User Data and Financial Info
August 4, 2026
A Bitdefender alert warns that Roblox players are being targeted by a fake Xeno Executor mod marketed as delivering “undetected” status, but it actually delivers malware.
Victims’ data exposed by the scam includes passwords, browser cookies, tokens for services such as Discord and Roblox, and payment data, enabling account takeovers and financial theft.
Beyond data theft, the malware enables surveillance and full control, capable of logging keystrokes, tracking mouse movements, capturing screenshots, streaming desktop activity, accessing the webcam, and permitting file transfer and PowerShell commands.
The campaign appears to have peaked in March 2026 and remains active, leveraging the lure of cheats and the promise of an “undetected” tool to reach Roblox’s 82 million players.
The infection chain installs a Java-based remote access trojan (RAT) and an infostealer that harvests browser data, online accounts, payment information, and cryptocurrency wallet data, including Exodus Wallet.
Xeno Executor is an unofficial Roblox script executor that Roblox blocks with new versions, and criminals exploit this by distributing fake variants on forums and Discord communities.
Summary based on 1 source
